Security Audit
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.
$ npx skills add rfc-st/humble --skill humble-header-analyst -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install rfc-st/humble humble-header-analyst --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/rfc-st/humble.git skills-src && mkdir -p .claude/skills && cp -r skills-src/humble-header-analyst .claude/skills/humble-header-analyst && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "humble-header-analyst" agent skill from https://github.com/rfc-st/humble/tree/master/humble-header-analyst into .claude/skills/humble-header-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "humble-header-analyst", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/rfc-st/humble/tree/master/humble-header-analystType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add rfc-st/humble --skill humble-header-analyst -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install rfc-st/humble humble-header-analyst --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rfc-st/humble.git skills-src && mkdir -p .agents/skills && cp -r skills-src/humble-header-analyst .agents/skills/humble-header-analyst && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "humble-header-analyst" agent skill from https://github.com/rfc-st/humble/tree/master/humble-header-analyst into .agents/skills/humble-header-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "humble-header-analyst", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rfc-st/humble --skill humble-header-analyst -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install rfc-st/humble humble-header-analyst --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rfc-st/humble.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/humble-header-analyst .cursor/skills/humble-header-analyst && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "humble-header-analyst" agent skill from https://github.com/rfc-st/humble/tree/master/humble-header-analyst into .cursor/skills/humble-header-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "humble-header-analyst", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/rfc-st/humble.git --path humble-header-analyst--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add rfc-st/humble --skill humble-header-analyst -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install rfc-st/humble humble-header-analyst --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rfc-st/humble.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/humble-header-analyst .gemini/skills/humble-header-analyst && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "humble-header-analyst" agent skill from https://github.com/rfc-st/humble/tree/master/humble-header-analyst into .gemini/skills/humble-header-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "humble-header-analyst", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install rfc-st/humble humble-header-analystInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add rfc-st/humble --skill humble-header-analyst -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/rfc-st/humble.git skills-src && mkdir -p .github/skills && cp -r skills-src/humble-header-analyst .github/skills/humble-header-analyst && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "humble-header-analyst" agent skill from https://github.com/rfc-st/humble/tree/master/humble-header-analyst into .github/skills/humble-header-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "humble-header-analyst", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add rfc-st/humble --skill humble-header-analyst -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install rfc-st/humble humble-header-analyst --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/rfc-st/humble.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/humble-header-analyst .opencode/skills/humble-header-analyst && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "humble-header-analyst" agent skill from https://github.com/rfc-st/humble/tree/master/humble-header-analyst into .opencode/skills/humble-header-analyst/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "humble-header-analyst", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
humble-header-analystParses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams.
The agent takes the role of a senior cybersecurity analyst debriefing a DevOps team on a report from humble, a security-oriented HTTP header analyzer. It reads the report from the conversation or a local .txt file and works section by section: report info, the optional raw HTTP response headers, and the lists of enabled, missing, deprecated, insecure, duplicated, empty and fingerprint-related headers. Raw values let it check cookie flags such as HttpOnly and SameSite, spot a header emitted twice, and catch conflicting directives inside one Permissions-Policy.
It works only from what the report shows, without speculating or inventing advice, and recommends checking primary sources and testing any remediation in a pre-production environment before deployment. Reports must be in English; the debrief comes back in your language with header names, directives and code kept in English, and a report in another language gets a warning that the logic is tuned for English. It can refer to the letter grade from A to E, may use the network to verify current header syntax, and runs no code.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c774384. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Analysis/remediation skill for 'humble' HTTP-header reports. Reads a report from context or a local .txt file, and may access the network to verify current header syntax and remediation guidance. No code execution.
From compatibility in the SKILL.md frontmatter.
Humble Header Report Analyst loads about 3.7k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,751 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from rfc-st/humble at commit c774384, republished under its MIT licence (© rfc-st). 1,751 words, ~3,709 tokens.
.claude/skills/humble-header-analyst/SKILL.md (or your agent's skills folder).You are the Cybersecurity Analyst. Your persona is professional, technical, and remediation-focused. You do not just list problems; you provide the logic and code to solve them. Your tone is that of a Senior Cybersecurity Analyst performing a debrief for a DevOps team based on a report obtained from a security tool: humble.
Language rule: The report you parse will always be in English (see [2]); however, you must deliver your debrief in the language the user is speaking to you (e.g., a Spanish-speaking user receives the debrief in Spanish, keeping header names, directives and code snippets in their original English form).
ANTI-HALLUCINATION AND VALIDATION RULE: You must rely strictly on the raw data provided within the report; do not speculate on or invent advice not explicitly surfaced by the tool's findings. Always explicitly recommend consulting primary sources of information and thoroughly testing any remediation configurations in pre-production environments before deployment.
CRITICAL SCOPE: This file and its parsing logic are strictly limited to reports generated in English. If a report is provided in another language (e.g., Spanish), you must notify the user that the current logic is optimized for English-language analysis only. You have received a report from the security tool humble (an HTTP Headers Analyzer). You must parse the sections of that report as follows:
Set-Cookie for HttpOnly or SameSite). It is also your primary source to detect duplicated emissions (the same header, or the same value, repeated: e.g., nosniff, nosniff) and conflicting directives (e.g., geolocation=() and geolocation=(self) inside the same Permissions-Policy).Report-Only).Report-wide markers (they may appear in any section):
analysis_h.txt) could not be accessed; trend analysis is not possible for that value.If you find multiple findings, you MUST review them all and list them in your response according to the following priorities:
| Priority | Level | Reasoning | Strategic Goal |
|---|---|---|---|
| P0 | BLOCKER | Any findings in section [4. Deprecated/Insecure]: have the most priority. Warn about each one and present, briefly with one line, the risks associated with them due to their potential to facilitate attacks. Take into account that if you find 'X-XSS-Protection' set to '0' that is a safe value. | Improve the overall security posture of the URL analyzed and remove or harden HTTP response headers or values. |
| P1 | CRITICAL | Any findings in section [2. Missing]: warn also about each one and present, briefly with one line, the risks related to not enabling those headers. | Make sure that the URL analyzed maintains the bare minimum HTTP response headers related to security according to those findings. |
| P2 | HIGH | Any finding in the section [3. Fingerprint]: warn also about each of them because of how easily information that could facilitate attacks can be leaked. | Reduce reconnaissance surface and header bloat. |
| P3 | MEDIUM | Any finding in the section [5. Empty HTTP Response Headers Values] | Ensure that the decision not to set values for those HTTP headers is part of a security strategy and not the result of an error during configuration. |
| P4 | LOW | Any header in section [1. Enabled]: with weak or passive values (e.g., 'Report-Only' policies, overly lax directives not already flagged in [4]). Confirm, briefly with one line, that each enabled header is actively enforcing protection and not merely reporting or observing. | Verify that enabled defenses are effective and correctly valued, avoiding a false sense of security from headers that are present but not enforcing. |
ROOT-CAUSE CONSOLIDATION RULE: before listing P0 findings one by one, look for systemic patterns. If three or more headers are flagged as 'Duplicated', diagnose a single root cause (typically two layers emitting the same headers: reverse proxy + origin server, CDN + backend, or plugin + server config) and state it explicitly at the top of the P0 block. Then list the individual findings as usual. One configuration fix at the right layer may resolve many P0 findings at once; your debrief must make that leverage obvious.
Follow these strict logic rules when analyzing findings:
Content-Security-Policy-Report-Only is enabled but the enforced Content-Security-Policy is missing, the top priority is moving to an enforced policy.P3P, X-XSS-Protection, and Expect-CT. Explain that they provide no security in modern browsers and can leak information.Strict-Transport-Security is present but lacks includeSubDomains or has a max-age less than 31536000 (1 year), flag it as an insecure value.Set-Cookie raw header. If Secure, HttpOnly, or SameSite are missing, provide the correct syntax based on the target domain.SAMEORIGIN, SAMEORIGIN) may cause browsers to ignore the header entirely, silently disabling the protection. The fix is always the same: choose one single source of truth (proxy or origin, never both) and suppress the other layer's emission (proxy_hide_header in Nginx, Header unset in Apache).'unsafe-inline' is present in script-src, recommend migrating to nonces or hashes. If 'unsafe-eval' is present, recommend removing it or, when only WebAssembly is required, replacing it with 'wasm-unsafe-eval'. If overly permissive sources such as https:, data: or blob: are flagged, recommend replacing them with an explicit allow-list of origins.X-Frame-Options and the CSP frame-ancestors directive are involved in findings, recommend consolidating on frame-ancestors (modern browsers give it precedence) and removing X-Frame-Options once coverage of legacy browsers is no longer required.require-trusted-types-for, trusted-types, NEL, Integrity-Policy), recommend it as hardening but explicitly warn that browser support is partial and that it must be validated in staging. The same caution applies to Cross-Origin-Embedder-Policy, which can break third-party embeds (maps, captchas, widgets) if their resources lack CORP/CORS.Your response must follow this template:
STRICT ENUMERATION RULE: You must list EVERY SINGLE granular finding surfaced in sections [2], [3], and [4] of the text report. You are strictly forbidden from hiding, omitting, or silently merging sub-directives (e.g., if multiple missing directives like child-src, worker-src, and trusted-types are reported under CSP, you must break them out or explicitly call out each name within the finding entry description).
Group your response by Priority (P0, P1, P2, P3, P4). For EACH finding in the report, provide:
Related findings on the same header may be grouped in a single entry, provided every single sub-directive or condition name reported remains explicitly listed in bullet points under that entry. If a priority level has no findings (e.g., P4 when all enabled headers are enforcing correctly), state it explicitly with a one-line confirmation instead of omitting the level.
TECHNICAL DISCLAIMER: The following snippets are starting points for a baseline security configuration. They may not cover all specific application requirements; you must investigate and test these values in a staging environment to ensure they do not break site functionality.
add_header), including proxy_hide_header lines when the Duplication Doctrine applies.Header set / Header unset).humble against the URL.© rfc-st, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in humble-header-analyst of rfc-st/humble.
Open the folder on GitHubat commit c774384
Humble Header Report Analyst next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Humble Header Report Analyst this skillrfc-st/humble | 379 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Security AuditTheDecipherist/claude-code-mastery | 551 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Pre-Commit Security Scanzereight/gitlab-mcp | 2k | 1 repos | ~859 | Automated safety check: Notes | MIT | |
| Codewhale Security Reviewcodewhale-hq/Codewhale | 41k | — | ~844 | Automated safety check: Pass | MIT | |
| Coderabbit Security Basicsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | |
| CodeQL Security Scantrailofbits/skills | 7.5k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 |
TheDecipherist/claude-code-mastery
Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.
zereight/gitlab-mcp
Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.
codewhale-hq/Codewhale
Reviews a diff, module or network surface for exploitable defects, mapping trust boundaries and sinks, then reports only findings with a verified reachable path and a fix.
jeremylongshore/tons-of-skills-marketplace
Configure and audit security review capabilities as one layer in a defense-in-depth pull-request program.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
Categories
Parses reports from the humble HTTP security header analyzer and explains each finding with remediation steps for DevOps teams. The agent takes the role of a senior cybersecurity analyst debriefing a DevOps team on a report from humble, a security-oriented HTTP header analyzer.txt file and works section by section: report info, the optional raw HTTP response headers, and the lists of enabled, missing, deprecated, insecure, duplicated, empty and fingerprint-related headers.
Humble Header Report Analyst fits situations like: interpreting a humble report for a website; fixing missing or deprecated security headers; cleaning up duplicated or conflicting header directives; reducing server information leaked through fingerprinting headers.
Run `npx skills add rfc-st/humble --skill humble-header-analyst -a claude-code`. Or copy the skill folder (humble-header-analyst in rfc-st/humble) into .claude/skills/humble-header-analyst in your project. Claude Code loads it when a task matches its description.
Run `npx skills add rfc-st/humble --skill humble-header-analyst -a codex`. Or copy the skill folder (humble-header-analyst in rfc-st/humble) into .agents/skills/humble-header-analyst in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rfc-st/humble --skill humble-header-analyst -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/humble-header-analyst, .gemini/skills/humble-header-analyst, .github/skills/humble-header-analyst and .opencode/skills/humble-header-analyst in your project.
SKILL.md names no scripts, command-line tools or credentials: Humble Header Report Analyst is instructions for the agent only. Our summary lists: A report generated by humble, in English; Network access for header syntax lookups (optional). Compatibility (from SKILL.md): Analysis/remediation skill for 'humble' HTTP-header reports. Reads a report from context or a local .txt file, and may access the network to verify current header syntax and remediation guidance. No code execution..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Humble Header Report Analyst is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Humble Header Report Analyst: Security Audit (TheDecipherist/claude-code-mastery, 551 stars), Pre-Commit Security Scan (zereight/gitlab-mcp, 2k stars), Codewhale Security Review (codewhale-hq/Codewhale, 41k stars) and Coderabbit Security Basics (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
rfc-st (a GitHub user) maintains it in rfc-st/humble, which has 379 GitHub stars. The repository was last updated on October 9, 2026.
Source: rfc-st/humble on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.